Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10BA161306814553B076392DAB62BBB06BAD6C348C7171585AEFCD7BD0FE2C90DC67A24 |
|
CONTENT
ssdeep
|
96:nkX75q0jYv5Kdif+oA74jaeu1SPKDaB9AMOF5JGWcj/OynX:kX75q0jYhfNFaeuogasMgGfb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b90770d48631e3eb |
|
VISUAL
aHash
|
0000011fffffcfff |
|
VISUAL
dHash
|
cce1cbfee11c1e1a |
|
VISUAL
wHash
|
0000000fffffcfcf |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
cbeef6c0189e1f1a,a181c0acacc081a1,ccc42ec1dbcefef6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 57 techniques to evade detection by security scanners and make reverse engineering more difficult.